Ruckus ICX VLAN and VE Interface Configuration - 夜莺博客

Ruckus ICX VLAN and VE Interface Configuration

Ruckus ICX switches run FastIron, a CLI that predates the Brocade-to-Ruckus transition and still shows it: VLAN membership is configured inside the VLAN, not on the port, and Layer 3 interfaces are virtual ethernet (VE) interfaces that have to be explicitly bound to a VLAN. Once that mental model clicks, the configuration is short. This article covers a complete VLAN deployment, dual-mode ports, and the verification commands that confirm what a port is actually carrying.

Creating a VLAN and adding ports

device# configure terminal
device(config)# vlan 10 name Sales
device(config-vlan-10)# untagged ethernet 1/1/5 to 1/1/10
device(config-vlan-10)# tagged ethernet 1/1/24 to 1/1/26
device(config-vlan-10)# exit
!
device(config)# vlan 20 name Engineering
device(config-vlan-20)# untagged ethernet 1/1/11 to 1/1/20
device(config-vlan-20)# exit

Two things to internalise. First, ports are declared untagged (single-VLAN access) or tagged (802.1Q trunk member) from inside the VLAN — there is no switchport mode. Second, a port that is untagged in one VLAN cannot be untagged in another; the second command is refused rather than silently taking effect.

Dual-mode ports: an access VLAN plus tagged VLANs

device(config)# interface ethernet 1/1/30
device(config-if-e1000-1/1/30)# dual-mode
device(config-if-e1000-1/1/30)# dual-mode 20
device(config-if-e1000-1/1/30)# exit
!
! ports 1/1/24-26 already carry VLAN 10 tagged; add VLAN 20 tagged
device(config)# vlan 20
device(config-vlan-20)# tagged ethernet 1/1/24 to 1/1/26
device(config-vlan-20)# exit

Dual-mode is the FastIron equivalent of a voice VLAN setup: the port accepts untagged traffic in its access VLAN and tagged traffic in the specified VLAN on the same cable. It is common on ports that carry an IP phone with a PC behind it.

Layer 3: router-interface ve

device(config)# vlan 10
device(config-vlan-10)# router-interface ve 10
device(config-vlan-10)# exit
!
device(config)# interface ve 10
device(config-vif-10)# ip address 10.0.10.1 255.255.255.0
device(config-vif-10)# exit
!
device(config)# vlan 20
device(config-vlan-20)# router-interface ve 20
device(config-vlan-20)# exit
!
device(config)# interface ve 20
device(config-vif-20)# ip address 10.0.20.1 255.255.255.0
device(config-vif-20)# exit
!
device(config)# ip route 0.0.0.0 0.0.0.0 10.0.10.254

Note that VE numbering is arbitrary — ve 10 is just an interface number, and the binding to VLAN 10 is made by router-interface ve 10 inside the VLAN. Inter-VLAN routing requires IP routing to be enabled on the platform (ip routing on ICX 7xxx/8xxx series; the lower-end ICX 6xxx are Layer 2 only, which is a hardware limit rather than a configuration mistake).

Verification

device# show vlan
device# show vlan 10
device# show interfaces brief
device# show interfaces ethernet 1/1/30
device# show ip interface
device# show ip route
device# show running-config vlan

show vlan prints each VLAN with its port lists and tag state — the fastest way to spot a port that was added to the wrong VLAN or that is still in the default VLAN 1. show interfaces ethernet per port shows link state, speed, duplex and VLAN membership together, which is where you catch a duplex mismatch masquerading as a VLAN fault.

Failure patterns

  • Port added to a VLAN but no traffic — the port is still untagged in the default VLAN. show vlan makes both memberships visible.
  • Uplink passes one VLAN and not others — the VLAN was added untagged on one end and tagged on the other. Both ends must agree per VLAN.
  • VE interface up but no routing — the VE was assigned an address but never bound with router-interface ve inside the VLAN, or IP routing is not enabled.
  • Dual-mode port has no access VLAN — dual-mode without a preceding untagged membership leaves the port with no untagged VLAN at all.
  • Configuration lost on reboot — FastIron keeps running and startup configurations separately; use write memory (or copy running-config startup-config) before reloading.

Related material: Ruckus ICX stacking setup and member roles for the stack side of the same platform, Extreme EXOS VLAN configuration for a closely comparable CLI model, and ArubaOS-Switch VLAN and trunk configuration if you are standardising on a single campus vendor.

原文链接:https://docs.commscope.com/bundle/fastiron-10010-l2guide/page/GUID-A3212EBD-0D44-4698-8798-7B9DD9560687.html